Part V of the Cybercrime Code Act 2016 contains two sections, both directed at ICT service providers. Section 44 is the liability provision.
Section 44(1) — five limbs, one penalty
(a) intentionally or knowingly, and without lawful excuse or justification or in excess of one, monitors the information which they transmit or store on behalf of their users, or actively seeks facts or circumstances indicating illegal activity by their users; or
(b) intentionally or without lawful excuse or justification, or in excess of one, initiates or aides in facilitating the action which results in the commission of an offence under this Act or which results in the contravention of any other law in force in Papua New Guinea; or
(c) knowingly or upon knowledge of criminal investigations or proceedings, undertakes or omits to undertake an act, thereby concealing, preventing or frustrating them; or
(d) does not comply with an order by the Court requiring it to assist law enforcement, or to terminate or prevent an action; or
(e) negligently allows an employee to commit an offence under paragraph (a), (b), (c) or (d).
Penalty: natural person — a fine up to K100,000 or imprisonment up to 25 years, or both; body corporate — a fine up to K1,000,000.
Paragraphs (c) and (d) are dealt with in the article on court orders, and paragraph (e) in the article on employee conduct.
Paragraph (a) — monitoring is the offence
Section 44(1)(a) does not punish a provider for failing to monitor. It punishes a provider for monitoring.
Two limbs:
- Monitoring the information the provider transmits or stores on behalf of their users; and
- Actively seeking facts or circumstances indicating illegal activity by their users.
Both are made offences, punishable by 25 years, unless done with lawful excuse or justification.
The provision reflects a policy familiar from comparable legislation elsewhere: a carrier or host should be a conduit, not a censor. Requiring providers to inspect user traffic would make them the arbiters of what passes through their networks, and would convert every service into a surveillance mechanism.
See whether a provider can monitor its users for the lawful excuses that make ordinary network operation possible.
Paragraph (b) — initiating or aiding
Initiates or aides in facilitating the action which results in the commission of an offence under this Act, or which results in the contravention of any other law in force in Papua New Guinea.
“Any other law”. As with section 31, the offence facilitated need not be a cybercrime offence. It may be a contravention of any law in force.
“Initiates or aides in facilitating”. Two levels of involvement — starting the action, or helping to facilitate it. Both require the provider to have done something; mere carriage of a user’s traffic is not initiating or aiding.
The mental element. The conduct must be intentional, and without lawful excuse or justification, or in excess of one. There is no recklessness limb in paragraph (b), and no negligence limb — negligence appears only in paragraph (e), and only in relation to an employee.
The tension between (a) and (b)
Read together, the two paragraphs place a provider in a narrow position. It may not inspect what its users send or store, and it may not aid in facilitating an action that results in an offence.
The reconciliation lies in the mental elements. Paragraph (b) requires intentional conduct that initiates or aides. A provider that does not look, and therefore does not know, has not intentionally aided anything.
What changes the position is knowledge. Once a provider is told — by a complainant, by police, or by a court order — that particular material or activity on its service is unlawful, continuing to carry it is a different matter, and paragraphs (c) and (d) come into play.
That is why a documented notice and response process is the central compliance measure for any provider: it establishes what the provider knew and when, and what it did about it.
Who this applies to
Schedule 1 describes seven categories: telecommunications service providers, internet service providers, access providers, caching providers, hyperlink providers, web hosting providers, and website masters or administrators.
The last of those is a person, not a business. Anyone responsible for maintaining a website is within Part V — and therefore within the 25-year exposure in section 44.
See also section 45, which makes disclosure of a confidential investigation a separate crime.
Sources
- Cybercrime Code Act 2016 — ss 1, 2, 31, 44, 45; Schedule 1
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.